Vestalet
Our solution, Vestalet, simplifies how people rent, buy, and exchange homes. It is a secure, cloud-based platform that connects housing providers and customers through intuitive digital services, streamlining property listings, enquiries, and tenant engagement to deliver a transparent, modern housing experience via browser and dedicated mobile app.
Features
- Unified digital platform for lettings, sales and mutual exchanges
- Web-based access via desktop and mobile devices
- Intelligent property search and matching with configurable filters
- Tenant self-service for registrations, expressions of interest and exchanges
- Provider dashboard for managing listings, enquiries and applicant data
- Automated notifications, reminders and status updates
- Secure cloud-hosted platform aligned with UK data protection requirements
- Configurable workflows to support lettings and sales schemes
- API-enabled integration with housing management and CRM systems
- Scalable architecture to support organisations of varying sizes
Benefits
- Property lettings, sales and exchange processes through a single platform
- Reduces administrative effort through automation and self-service
- Improves customer experience with clear, transparent digital journeys
- Accelerates matching of applicants to suitable homes
- Increases operational efficiency for housing and local authority teams
- Enhances data consistency across housing and customer systems
- Supports digital transformation and modern service delivery
- Improves accessibility with mobile-friendly, intuitive design
- Scales easily to meet changing demand and portfolio size
- Builds trust through secure handling of customer and property data
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 1 6 8 4 6 9 8 2 7 3 2 9 6 8
Contact
INCLINE IT LIMITED
Sales
Telephone: 0845 330 3225
Email: sales@incline-it.com
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Support is supplied remotely. Standard Support hours are Monday to Friday 8:00am to 6:00pm, however enhanced Support Hours can be purchased if required.
- System requirements
- Internet or data connection
User support
- Email or online ticketing support
- Yes
- Support response times
- Critical incidents - Immediate High - 10 Minutes Medium - 1 Hour Low - 4 Hours Very Low - 1 Day
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We provide a tiered support model aligned to a defined Incident Response Matrix. Priority 1 (Critical) incidents receive immediate response with a one-hour target resolution inside business hours and two hours outside. Priority 2 (High) incidents receive a 10-minute response and four-hour resolution. Priority 3 (Medium) incidents receive a one-hour response and eight-hour resolution. Priority 4 (Low) incidents receive a four-hour response and 24-hour resolution, while Priority 5 (Very Low) incidents receive a one-day response and one-week resolution. All support levels are included within our standard support service; there are no uplifted charges for higher-priority incidents. Support outside of business hours is available at an extra cost. We provide access to a technical and support staff as the required to assess and resolve the support issue. The staff offer proactive guidance, environment familiarity, and escalation management to ensure efficient issue resolution and ongoing operational assurance.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Customers are pre-set in the solution, meaning that customers can log in and claim access to their account. Users must complete some initial checks to ensure that they truly represent the customer.
Once inside the solution, we guide the users through the onboarding journey with videos, documentation and a call if the need arises. Configuration takes less than an hour. Data imports are available at the appropriate points and documentation is available to support their use.
Agentic AI will be available in the future to support the onboarding and ongoing maintenance of the solution.
New features will be regularly released and additional guidance will be provided for each release. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Videos
- End-of-contract data extraction
-
The service is a pay-as-you-go service and data can be exported by the users at any point.
In the event that the solution is not utilised for 3 months then we will reach out to the customers. In the event that the solution is not accessed for 6 months then we will suspend the account. - End-of-contract process
-
Upon termination, the account is suspended. As the solution is intended only for social housing providers, we maintain all social housing providers in the solution ready for use.
Extracting data is at no charge. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The configuration and management of Vestalet for administrators is accessed by browser only. The Vestalet end user application can be accessed via Web Browser on devices or via the dedicated iOS or Android Mobile App.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Vestalet provides a browser-based, intuitive service interface that enables admin users to manage connectivity and customisation options from a single workspace.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have not conducted any interface testing of the service interface with users of assistive technology at this time.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Users can customise Vestalet to align with their organisation’s policies, and operational processes through a range of configurable administrative features.
What can be customised: Customisation includes creating allocations and sales policies aligned to operational policies.
How users can customise: Customisation is completed via the configuration options in the secure Admin interface. Admin users configure settings using built-in tools.
Who can customise: Customisation is restricted to authorised administrative users within the customer organisation. Admin access is role-based and secured using Single Sign-On (SSO) linked to the organisation’s identity provider, ensuring only approved staff can make changes.
Scaling
- Independence of resources
-
Our serverless architecture ensures total performance isolation by scaling compute resources horizontally for every request, preventing any single user from monopolising capacity. We utilise Valkey as a high-speed caching and rate-limiting layer, shielding the core Postgres database from traffic spikes and ensuring millisecond response times for administrators, with the presentation layer for end users all cached in AWS CloudFront
Furthermore, by offloading intensive analytical queries to S3, we "air-gap" heavy reporting from the live bidding engine. This multi-layered approach, combining elastic scaling, distributed caching, and data decoupling, guarantees consistent, lightning-fast performance for all users, regardless of aggregate platform demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Our platform delivers comprehensive metrics across four key pillars, these would be accessible via AWS Athena which can be accessed from PowerBI and other industry standard tools.
Demand & Bidding: Monitor applicant distribution by priority band, bid density per property, and digital engagement levels.
Operational Efficiency: Track void turnaround times, refusal reasons, and bid-to-let ratios to streamline allocations.
Social Impact: Report on equality, diversity, and homelessness prevention to meet regulatory requirements (e.g., CORE).
Strategic Trends: Use longitudinal data to forecast long-term housing demand and supply alignment.
This architecture ensures high-performance reporting without impacting live system stability. - Reporting types
-
- API access
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Data exports are available within the solution as standard and available to users of the solution either in an output format or via an API.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
- API
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- API
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Customer Hub is hosted with Amazon Web Services who have a 99.99% uptime SLA. It is based in AWS eu-west-2, which is the London Region. The service is spread across multiple availability zones for resilience. Our Terms and Conditions detail the process if guaranteed levels of availability are not met.
- Approach to resilience
- This information is available on request.
- Outage reporting
- If an outage were to occur, our customers would receive an email alert.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
-
We enforce a Zero Trust model using Role-Based Access Control (RBAC) to ensure staff only access data essential to their role. Management interfaces are secured via Multi-Factor Authentication (MFA)
Every administrative action is captured in immutable audit logs streamed to S3, enabling forensic oversight via Athena. By integrating with client Identity Providers (SSO), we guarantee immediate access revocation, maintaining a rigorous security posture across all management and support touchpoints. - Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- As an AWS Advanced Tier Partner, we integrate ISO 27001 principles, Confidentiality, Integrity, and Availability directly into our cloud-native architectures. We do not just deploy technology; we govern it through risk assessments and automated guardrails that satisfy both technical auditors and regulatory bodies. Our Non-Profit Competency allows us to tailor this high-level security to the unique constraints of the sector. We provide non-profits with enterprise-grade security that is cost-optimized, utilizing AWS grants and ethical licensing models to ensure that mission-critical funds are preserved. By coupling ISO 27001 governance with specialized AWS validations, we provide security aligned to risk based and technical controls and assessments, ensuring trust and data privacy. This holistic approach transforms compliance from a hurdle into a strategic asset, enabling organisations to scale their social impact on a globally recognized, secure foundations.
- Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We track all service components from deployment to retirement using Infrastructure as Code (IaC) templates and AWS Config, which maintains a continuous inventory and version history of all resources. Every change undergoes a mandatory Security Impact Assessment via our CI/CD pipeline, where automated tools perform Static Code Analysis and check against the CIS AWS Foundations Benchmark v5.0.0. High-impact changes require a manual peer review and "Security Sign-off" before merging. This ensures that every modification is documented, authorized, and validated for risk, meeting CSA CCM v4 and ISO 27001 change control standards.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We assess potential threats through a continuous lifecycle: pre-deployment Static Code Analysis (SAST) catches vulnerabilities early, while daily AWS Inspector scans monitor our live infrastructure. Every two weeks, we conduct AWS Security Hub reviews against the CIS AWS Foundations Benchmark v5.0.0 to identify misconfigurations. For deep validation, we perform annual Penetration Tests and secondary tests for all Major Releases. Our risk-based patching SLA ensures Critical vulnerabilities are addressed within 14 days, High within 30 days, and lower risks during standard maintenance. Threat intelligence is sourced directly from AWS GuardDuty, CVE databases, and CIS advisory feeds.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We proactively identify compromises using Amazon GuardDuty for intelligent threat detection and AWS Security Hub, which provides bi-weekly posture reviews against CIS v5.0.0. Daily AWS Inspector scans and annual penetration tests act as early-warning systems for exploitable gaps. Upon detecting a potential compromise, we initiate our Incident Response Plan, isolating affected resources (e.g., via Security Groups) and performing root-cause analysis using AWS CloudTrail logs. We commit to a 4-hour response time for critical security alerts, with 24/7 automated paging for critical-severity findings to ensure rapid containment and minimal business impact for customers who require 24/7 support.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We maintain a formal Incident Response Plan with pre-defined playbooks for common events like unauthorized AWS access or malware detection, triggered by AWS Security Hub (CIS v5.0.0) and GuardDuty. Users report incidents via a dedicated Security Portal or an internal 24/7 emergency alias. We prioritize containment within 4 hours for critical events. Following resolution, we provide Post-Incident Reports (PIRs) to stakeholders, detailing the root cause analysis from AWS CloudTrail, impact assessment, and remediation actions. This process aligns with ISO 27001 and CCM v4 (SEF domain) for continuous security improvement
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Saturday 6 March 2021
- What the ISO/IEC 27001 doesn’t cover
- We have completed statement of applicability with 100% coverage to the standard.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Alcumus ISOQAR
- ISO 9001 accreditation date
- Monday 13 July 2020
- What the ISO 9001 doesn’t cover
- We have 100% coverage under the QMS
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6efd269c-74fa-4ea4-915d-0025386416c3
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- ISO 27001
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-